Impact
Improper authentication in the PAM configuration allows a local attacker to log in as a uid=0 account without a password by creating an entry in /etc/passwd with an empty password field. The result is a root shell, giving the attacker full control of the affected device. This flaw falls under CWE-287 (Improper Authentication) and CWE-521 (Plaintext Storage of Password).
Affected Systems
All Loytec LINX firmware products including LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑VIS, and L‑PAD are affected through firmware versions up through 8.4.16.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of less than 1% signals a low yet non-zero likelihood that the vulnerability will be actively exploited. Because the attack requires local access to the device, the flaw is not remotely exploitable, but it remains a significant concern in environments where physical or local console access is possible. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment